Getting Data In

Splunk indexing question

webelieve1111
Engager

Hi,
I am trying to estimate how much indexing I would need from my setup for Splunk and was wondering exactly how indexing is calculated. I know from documentation that there are 2 types of files: compressed data and index files. For Splunk Free, would both the compressed data and index files count towards the 500MB/day or would it just be the index files?

Thanks!

0 Karma
1 Solution

Gilberto_Castil
Splunk Employee
Splunk Employee

Splunk licensing is measured by the volume of data consumed in a daily basis. If you consume 500MB of raw data, then your license will count 500MB.

The licensing is not measured by the amount of data you keep stored with your Splunk instance.

View solution in original post

bmacias84
Champion

If you are using the free version of Splunk you can only index 500mb per day. The 500MB per day consists of raw data defined within your inputs.conf files on your indexers and forwarders and excludes Splunk internal logs.

To estimate how much data you will be indexing look at how large the log files are and multiply by number of logs. Do that for each set of logs for a rough estimate.

If you want to calculate disk storage requirements read this: EstimateIndexSize

Hope this helps and gets you started. CHeers.

Gilberto_Castil
Splunk Employee
Splunk Employee

Splunk licensing is measured by the volume of data consumed in a daily basis. If you consume 500MB of raw data, then your license will count 500MB.

The licensing is not measured by the amount of data you keep stored with your Splunk instance.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...